ZeroHour

CVE-2022-22960

KEV PoC ×3large

Local Privilege Escalation in VMware Workspace ONE Access, Identity Manager and vRA

CISA: VMware Multiple Products Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
36%p98
Published
()
KEV added
AI analysis

VMware Workspace ONE Access, VMware Identity Manager and vRealize Automation virtual appliances contain a local privilege escalation flaw (CWE-250, execution with unnecessary privileges): support scripts shipped with the appliances have improperly set permissions and run with elevated privileges. An attacker who already has some form of local or shell access to an affected appliance can modify or abuse these scripts to execute code as root (per VMware's advisory), gaining full control of the appliance, its identity/directory data and a platform for persistence and pivoting. Organizations running these VMware identity- and cloud-automation appliances are affected, since the weakness is in the appliance software itself; risk is highest where the appliances are reachable or where this bug is chained with other recently disclosed VMware appliance vulnerabilities. The flaw is known exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-15, and EPSS assigns a high 35.8% probability of exploitation within 30 days (98th percentile), although no public PoC is known and ransomware use is unconfirmed.

What to do: Apply the patched appliance releases per VMware's instructions, as required by CISA's KEV listing; until patched, restrict local, shell and management-plane access to Workspace ONE Access, Identity Manager and vRealize Automation appliances, and review them for unexpected root-level activity or modified support scripts. Treat this as actively exploited and prioritize patching alongside the other flaws fixed in the same VMware advisory.

Affected
VMware Workspace ONE Access
VMware Identity Manager
VMware vRealize Automation
Estimated exposure
largetens of thousands of enterprise appliance deployments worldwide (order of magnitude 10^4) — No public install counts are published, but these products ship as virtual appliances deployed across VMware's large enterprise customer base for identity management and private-cloud automation, and sibling Workspace ONE flaws from the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'.

CISA Known Exploited Vulnerability
Affected
VMware Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
vmware
Products
cloud foundation, identity manager, vrealize automation, vrealize suite lifecycle manager, workspace one access
Weakness
CWE-732
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news